Home

Phishing & Wallet Drainers

QR Code Phishing (Quishing): How Malicious QR Codes Target Crypto Wallets

Spot the edge. Swoop in.

A poster at a conference, a payment terminal at a meetup, an email that says "scan to verify your wallet" — QR codes are everywhere in crypto, and unlike a typed link, you can't read where one leads before you scan it. This guide breaks down how "quishing" attacks swap physical codes, fake WalletConnect pairings, and hide phishing links inside a square of black-and-white pixels, so you can catch the scan before it costs you anything.

By Swoopr Editorial Team

Published · Updated

AI-assisted content · Swoopr is responsible for the final published article.

Key Takeaways

A QR code is nothing more than a URL, a wallet address, or a WalletConnect pairing string encoded as a scannable grid of squares. Everything a typed link can do, a QR code can also do — including leading to a phishing site or a malicious wallet-connection request. The difference is what makes QR codes a distinct attack surface worth its own guide: with a typed or pasted link, you can hover, zoom in, or read the domain character by character before you click. With a QR code, that inspection step is gone by default. You commit to a destination the instant your camera decodes the pattern, unless your scanning tool specifically shows you a preview first.

Direct answer: QR code phishing ("quishing") works because a QR code hides its destination until scanned, and because crypto legitimately uses QR codes everywhere — wallet addresses, WalletConnect pairing, exchange logins, in-person payments — which makes a malicious code blend into normal behavior instead of standing out. Attackers exploit this by physically swapping real codes for fake ones on event signage and payment terminals, embedding malicious codes in "verify your wallet" or "claim your tokens" emails and DMs, and presenting fake WalletConnect pairing codes that connect your wallet to an attacker's interface instead of the one you meant to use.

Why QR Codes Are a Distinct Phishing Vector

Ordinary link-based phishing already has a well-known defense: look at the URL before you click it. A misspelled domain, an unfamiliar top-level extension, or a URL that doesn't match the sender's claimed identity are all things a careful reader can catch in the second or two before committing to a click. That defense depends entirely on the link being visible as text — something your eyes can parse — before any navigation happens.

A QR code breaks that defense structurally, not just practically. The information encoded in the pattern of black-and-white squares is unreadable to a human eye; it only becomes a URL, a wallet address, or a connection string after a camera or scanner decodes it, and by the time most phones or apps show you anything, they've often already opened the link or handed it to a browser. The inspection step link-based phishing training relies on simply doesn't exist by default for a QR code. You're not deciding whether to visit a destination you can read — you're deciding whether to trust a pattern you can't read at all, based only on where the code was printed or who appeared to send it.

The second half of what makes QR codes distinct in crypto specifically is how pervasive and legitimate their use already is. Sharing a wallet address by QR code avoids the error-prone process of typing or reading aloud a 42-character hexadecimal string. WalletConnect, the protocol that lets a mobile wallet approve actions on a desktop dApp, is built entirely around scanning a QR code to establish the session. Exchanges routinely offer QR-code logins and two-factor authentication setup. In-person crypto payments — a vendor at a conference, a tip jar at a meetup — are almost always QR-code driven, since typing out a full wallet address by hand isn't realistic. None of this is unusual or suspicious on its own; it's simply how crypto works day to day. That ubiquity is precisely the cover a malicious QR code exploits. A code asking you to scan and connect your wallet doesn't stand out in a space where that request is completely ordinary, which is exactly why it doesn't trigger the same instinctive caution a stranger asking for your seed phrase would.

Common Quishing Attack Patterns

Swapped or overlaid physical QR codes

Printed QR codes are trivially easy to replace. A sticker printed with a malicious code, sized to match the original, can be placed directly over a legitimate code on event signage, a sponsor banner, a printed flyer, or a payment terminal in the time it takes to walk past and press it down. Nobody watching a busy conference floor or a crowded meetup room is likely to notice a sticker being applied, and once it's there, everyone who scans it afterward is scanning the attacker's destination instead of the intended one. This pattern doesn't require compromising any account, cloning any website beyond what's necessary for the landing page, or gaining any special access — it only requires physical proximity to a printed code for a few seconds.

Malicious QR codes in phishing emails and DMs

Email and direct-message phishing has increasingly shifted toward embedding a QR code as an image rather than a clickable text link, partly because it's a novel enough format that some recipients haven't yet built the same reflexive suspicion toward it, and partly because a QR code image is harder for automated email-security scanners to flag than a visible malicious URL, since the destination isn't present as scannable text in the message body. The framing is almost always the same regardless of channel: a claim that something needs "verification," that funds or tokens are waiting to be "claimed," or that account access will be lost unless the code is scanned promptly. The QR code itself decodes to a phishing site built to harvest a seed phrase, request a malicious wallet connection, or capture exchange login credentials.

Fake WalletConnect pairing codes

WalletConnect's actual pairing flow is simple and, on its face, hard to distinguish visually from a fake one: a dApp interface displays a QR code, the user opens their wallet app and scans it, and a connection request appears asking to approve the session. Nothing about a QR code's appearance reveals whether the dApp presenting it is the legitimate site the user intended to visit or a cloned interface hosted on a look-alike domain. If the underlying page is fake — reached through a phishing link, a swapped physical code, or a manipulated search result — the WalletConnect QR code it displays will pair the wallet with the attacker's session instead. The wallet-side approval prompt is the last real checkpoint in this flow, and it's often skimmed quickly because the pairing step itself feels routine.

Worked Example: A Swapped QR Code at a Crypto Meetup

Hypothetical, generic example — for education only. Not based on any specific real event or organization.

Picture a mid-sized crypto meetup held at a co-working space, the kind of recurring local event with fifty to a hundred attendees, a couple of sponsor tables, and a printed schedule taped to the wall near the entrance. One sponsor table is staffed by a small project handing out merchandise and running a simple on-site promotion: attendees who scan a QR code on the table's tent card and connect a wallet get a small amount of a test token dropped into their address, a common and entirely ordinary practice at events like this.

Sometime between setup and the event's actual start, an attacker who walked in as a regular attendee approaches the table during a lull, and in a few seconds presses a pre-printed sticker directly over the tent card's original QR code. The sticker is sized and printed to closely match the original — same rough dimensions, a plausible white border — and from a normal viewing distance, nothing about it looks obviously out of place. The sponsor staff, focused on conversations with attendees rather than continuously monitoring their own signage, don't notice the swap.

Over the next hour, a steady stream of attendees walk up, scan the code, and are taken to a site that looks essentially identical to the sponsor's real promotional page — same logo, same color scheme, likely built by directly copying the visible assets from the real site. The page asks visitors to connect a wallet to "receive your drop," a request that matches exactly what the sponsor's real promotion was already asking for, so it raises no suspicion. Once connected, the site requests a signature framed as claiming the promotional token. In reality, the signature is a broad approval over an existing, more valuable token already sitting in some attendees' wallets. Nothing appears to go wrong at the moment of signing — no error, no obvious drain — which is exactly why several attendees don't realize anything happened until hours or days later, when assets move out of their wallets at a time of the attacker's choosing.

The tell here wasn't available by reading the QR code itself — it never is. It was available in exactly two other places: physically noticing that the sticker on the tent card looked slightly different from the surrounding printed material (a faint edge, a mismatched paper texture), and treating the wallet-connect and signature prompts with the same scrutiny that any unfamiliar site deserves, regardless of how legitimate the surrounding table and staff appeared. A QR scanner that previewed the destination URL before opening it would also have surfaced a domain that didn't match the sponsor's known site, catching the problem before any page even loaded.

"Scan to Verify" and "Scan to Claim" Deserve the Same Suspicion as Any Phishing Link

It's worth stating plainly: a QR code is not a different category of thing from a link. It is a link, encoded differently. Every heuristic that applies to an unsolicited email or DM containing a suspicious URL applies identically to one containing a suspicious QR code — an unexpected "verify your account" request, urgent language about expiring access, a claim that funds or tokens are waiting, or a sender you don't recognize are all the same red flags regardless of whether the malicious destination is presented as blue underlined text or a scannable square.

What changes with a QR code is only the defender's side of the equation, and it changes for the worse. A suspicious text link can be inspected — hovered over on desktop, long-pressed on mobile, or copied and read character by character — entirely before deciding whether to visit it. A QR code, scanned with a default camera app on many phones, frequently opens the decoded link immediately or with only a single, easy-to-dismiss tap, without ever displaying the underlying URL in a form most people stop to read. The QR format doesn't make the underlying phishing attempt more sophisticated; it just removes the cheapest, most widely taught defense against it. Any "scan to verify," "scan to claim," or "scan to unlock" QR code arriving unsolicited, whether by email, DM, text message, or printed mail, should be treated with exactly the skepticism a matching text link would get — which, in nearly every legitimate context, means not scanning it at all and instead navigating independently to the account or site in question through a known, bookmarked URL.

Practical Defenses Against QR Code Phishing

None of the defenses below require special technical skill, and most take only a few extra seconds compared to scanning blindly.

Practical checklist

Common mistake

The common mistake isn't a lack of general caution — it's applying real caution to typed links while giving QR codes a pass, simply because they're unfamiliar enough not to trigger the same trained skepticism yet. A QR code should get at least the same scrutiny as a text link, not less, precisely because it's harder to inspect before committing to it.

Common Mistakes

Misconceptions Versus Reality

MisconceptionReality
QR codes are inherently more trustworthy than typed URLs because they're used for official things like WalletConnectThe legitimacy of the QR code mechanism says nothing about whether any individual code is trustworthy; WalletConnect's protocol being legitimate doesn't stop a fake dApp from displaying its own malicious pairing code
Scanning a QR code is inherently more dangerous than clicking a link, since it could contain malwareA QR code is almost always just an encoded URL or connection string, not executable code; the danger comes from where the link leads and what you do after, the same as any other phishing link
If a QR code is printed on official-looking signage or professional materials, it must be genuinePrint quality and placement say nothing about authenticity; a sticker printed to closely match the original can be placed over a legitimate code in seconds
My phone would warn me if a QR code led somewhere dangerousMost default camera apps decode and offer to open a link with no safety evaluation at all; a URL preview only appears if the specific scanner app you're using is built to show one
A QR code in an email from a company I recognize must be safe to scanSender identity in email and DMs is trivially spoofable, and QR-code phishing is increasingly used specifically because it's less likely to be flagged by automated security scanning than a visible malicious link
Approving a WalletConnect session is a low-risk, routine actionA WalletConnect approval can grant a connected dApp interface the ability to request signatures and transactions from your wallet; approving a session with an attacker-controlled interface carries the same risk as connecting to any other malicious site

Prevention Checklist

These habits address QR code phishing specifically, but they build directly on the same domain-verification and cautious-signing habits that defend against phishing generally.

Practical checklist

Risks, Limitations, and Exceptions

Tool Opportunity

A dedicated Swoopr tool should help readers safely preview what a QR code decodes to before committing to it, without exposing them to the destination it points to.

Recommended inputs: an uploaded photo or live camera capture of a QR code, and optionally the context in which it was encountered (email, DM, physical signage, payment terminal).

Expected outputs: the fully decoded URL or connection string displayed as plain, readable text without auto-navigating to it, a domain comparison against commonly impersonated or previously reported phishing domains where available, and a plain-language flag distinguishing a standard web link from a WalletConnect-style pairing request.

Validation requirements: never automatically open or navigate to the decoded destination, never request or store wallet credentials as part of the scan, clearly label domain-comparison results as heuristic signals rather than a definitive safety verdict, and direct ambiguous or unfamiliar domains toward manual verification through the entity's own official channels.

Sources

Frequently Asked Questions

What is QR code phishing ("quishing")?

QR code phishing, sometimes called quishing, is a phishing attack delivered through a QR code instead of a typed link. The code encodes a URL just like any other link, but because a QR code is a grid of black-and-white squares, a human can't read where it leads before scanning it, which removes the visual inspection step that catches many ordinary link-based phishing attempts.

Why are QR codes specifically dangerous in crypto?

Crypto uses QR codes constantly for entirely legitimate purposes: sharing a wallet address, pairing a wallet with a dApp through WalletConnect, logging into an exchange, or setting up two-factor authentication. That legitimate, everyday use is exactly what attackers rely on, because a QR code asking you to "scan to connect your wallet" or "scan to verify" looks completely normal in a space where that request is routine.

Can a QR code hack my phone or wallet just by scanning it?

In the overwhelming majority of cases, no. A QR code is almost always just an encoded URL or a WalletConnect pairing string, not executable code, so scanning it alone typically does nothing beyond opening a link or presenting a connection request. The risk comes from what happens after the scan: visiting a phishing site, approving a malicious WalletConnect session, or entering a seed phrase on a fake page.

How can I tell if a physical QR code has been tampered with?

Look for a sticker with slightly different paper stock, adhesive edges, printing quality, or alignment compared to the surface it's on, since attackers frequently print a malicious code on a sticker and place it directly over the real one. Also compare the code's surrounding text or branding to what you'd expect, and if anything is possible, verify the destination through a scanner that previews the URL before your phone navigates anywhere.

Is scanning a WalletConnect QR code always safe?

The WalletConnect protocol itself is a legitimate, widely used standard for pairing a wallet with a dApp, but the QR code presenting a pairing request can originate from a malicious or cloned interface just as easily as a real one. Always confirm the dApp name, URL, and requested permissions shown in your wallet's connection prompt match the site you intentionally navigated to before approving.

What should I do if I scanned a suspicious QR code?

If a page opened but you didn't enter any information, connect a wallet, or approve anything, close the page and avoid interacting with it further. If you connected a wallet or approved a WalletConnect session, immediately review and revoke the resulting session and any token approvals using a reputable approval-checking tool, and treat any wallet used to enter a seed phrase on the page as compromised.

Which Swoopr resource helps verify a link before scanning or clicking it?

The guide on how to verify a legitimate site covers the domain-checking habits that apply directly to whatever URL a QR code decodes to, and the broader Phishing & Wallet Drainers hub covers the underlying phishing and wallet-drainer mechanics a malicious QR code is typically used to deliver.

Conclusion

QR codes aren't a separate class of threat from ordinary phishing links — they're the same threat wearing a format that happens to remove your ability to inspect it first. That single difference is enough to make quishing effective even against people who'd never click an obviously suspicious text link, simply because the destination stays hidden until it's already too late to change course. The fix isn't avoiding QR codes, which are genuinely useful and deeply embedded in how crypto works day to day; it's restoring the inspection step wherever possible — a scanner that previews the URL, a careful look at printed signage for signs of tampering, and the same skepticism toward "scan to verify" that a matching typed link would get. Use this page alongside the broader Phishing & Wallet Drainers hub for the domain-verification and wallet-approval habits that apply across phishing generally, not just to QR codes.

Related Reading